Cybersecurity Risk & Exposure Analyst II

Invictus International Consulting, LLC

$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a technical discipline or 4 additional years of relevant experience.
  • Minimum 4 years of experience in cybersecurity-related roles.
  • Strong communication skills for technical documentation.
  • Proficient in vulnerability management and technical risk assessment.
  • Familiarity with ACAS/Tenable, runZero, and DoD STIG compliance.
  • Current DoD 8570 IAT II or IAM II certification required.
  • Experience in a DoD or Intelligence Community environment.

Responsibilities

  • Perform vulnerability and exposure analysis to support SOC investigations.
  • Correlate data from various sources to assess vulnerabilities.
  • Provide context to Cybersecurity Operations regarding identified weaknesses.
  • Coordinate findings with system administrators and remediation teams.
  • Analyze vulnerabilities to prioritize remediation and escalate systemic issues.
  • Develop checklists and procedures for operational analysis and monitoring.
  • Maintain detailed records of vulnerabilities and remediation efforts.

Benefits

  • Comprehensive health insurance options.
  • Retirement savings plans with employer contribution.
  • Paid time off and holidays.
  • Professional development opportunities.
  • Flexible work hours and potential for remote work.
Full Job Description
Title: Cybersecurity Risk & Exposure Analyst II

Location: Colorado Springs, CO

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details:
  • Independently perform operational vulnerability/exposure analysis and continuous-monitoring activities supporting SOC investigations, cyber risk prioritization, and system security coordination
  • Correlate ACAS/Tenable findings, runZero asset context, STIG/configuration information, system criticality, network/security telemetry, and other available data to assess the relevance and potential impact of identified weaknesses
  • Provide vulnerability, asset, configuration, and control context to Cybersecurity Operations and Threat Analysts during investigations and proactive analysis; identify known weaknesses that may contribute to exploitation or increase mission risk
  • Coordinate SOC-derived findings with system ISSOs/ISSMs, system owners, administrators, engineers, and remediation teams to validate affected assets, clarify risk, support mitigation, and determine required continuous-monitoring or RMF follow-up
  • Analyze recurring vulnerabilities, configuration weaknesses, and exposure patterns to identify remediation priorities and systemic conditions requiring escalation or broader corrective action
  • Develop and maintain repeatable checklists, procedures, and metrics for operational exposure analysis, remediation validation, SOC-to-ISSO coordination, and continuous-monitoring support
  • Maintain accurate records of findings, remediation status, risk decisions, tickets/actions, and supporting evidence in approved systems
  • Apply knowledge of network security, common protocols, system architecture, vulnerabilities, security controls, and DoD requirements to communicate technical risk in operational terms


Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum four (4) years of relevant experience in addition to education level
  • Strong written and verbal communication skills and the ability to document technical work clearly
  • Demonstrated knowledge of vulnerability management, asset and exposure analysis, DoD continuous monitoring, RMF/security controls, and technical risk assessment appropriate to the position level
  • Experience with ACAS/Tenable, runZero or comparable asset-discovery/exposure tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, security-control evidence, or comparable technologies and processes is desired
  • Ability to correlate vulnerability, asset, configuration, and system-security information and communicate operational risk to technical and compliance stakeholdersMust possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph


Similar Jobs

More Jobs at Invictus International Consulting, LLC

More Information Technology Jobs

Find similar Cybersecurity Risk & Exposure Analyst II jobs: